add-feishu

Warn

Audited by Socket on Feb 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The Feishu integration fragment is coherent and aligned with its stated purpose, leveraging the official Feishu SDK and a structured installer-like workflow. Key security considerations center on credential hygiene (secret storage/rotation, avoiding leaking into logs or VCS) and safeguarding the SQL path used to register chats (prefer parameterized queries). Overall risk is medium due to credentials and direct DB modifications, but no signs of malicious behavior. Recommendations: pin SDK versions, rotate secrets regularly, avoid writing secrets to loggable outputs or repository files, use parameterized SQL, and ensure .env is git-ignored and access-controlled.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 27, 2026, 11:42 AM
Package URL
pkg:socket/skills-sh/sugarforever%2F01coder-agent-skills%2Fadd-feishu%2F@6eee6888dd63efc6782c84229ab8338a78ef3bb0